SlideShare a Scribd company logo
1 of 19
Download to read offline
5 Astonishing Mistakes Made During 
GRC Projects 
in SAP Environments 
Created by Xpandion 
SAP® is a registered trademark of SAP AG in Germany and in several other countries
Moshe Panzer 
CEO, Xpandion 
Author
Xpandion has software to quickly maintain GRC 
Prevent fraud, save costs, quickly ensure SoD/SOX compliance. 
•Automate in-house and outsourced auditing tasks. 
•Receive alerts about unusual activities. 
•Prevent security breaches, fraud and leakage of information. 
•Save an average of 30% on auditing costs. 
•Ensure a successful audit. Get a free demonstration of Xpandion’s ProfileTailor GRC software to see what makes Xpandion different.
Mistake #1: 
The focus is on compensating controls, not on eliminating risk.
People don’t want to solve SoD conflicts either because they fear upsetting the user, or because they don’t want to pay for external consultants. Focusing on compensating controls may be “more comfortable” but it doesn’t solve risk.
The solution: 
Focus on solving the risks. Arm yourself with management support, GRC auditors and good consultants – but don’t be tempted to add compensating controls too quickly. Each control should be inspected first and then regularly inspected to ensure it’s still valid.
Mistake #2: 
Only Risk Assessment Managers & Auditors care about eliminating GRC risks.
GRC is a good thing. Its purpose is to decrease fraud and improve business processes. But, most people hate dealing with it. In the case of SOX compliance, many remove Power Users right before the audit and put them back right after. Anything to just get through. Shocking.
The solution: 
Get organized and gain management support by working your way up the GRC project ladder. 
Step 1: SoD inspection 
Step 2: Narrow Power User authorizations 
Step 3: Track sensitive activities usage 
Step 4: Implement one- step emergency access process with auditing reports 
Step 5: Implement authorization-request process
Mistake #3: 
After go-live, 
own developments are not treated properly.
Most people set groups of activities in the initial GRC project implementation and do not maintain them regularly, typically because they’ve forgotten about them. 
This results in potential hidden violations to Segregation of Duties rules.
The solution: 
Make it clear to management that the GRC project won’t be over at go-live as someone needs to keep an eye on the configuration, including enhancing the rule-sets according to new developments. 
It’s vital to add and update groups of activities over time. Use alerting software and get an alert when new objects appear in production. Then update the rule-set accordingly. 
Find out about Xpandion’s alerting software.
Mistake #4: 
Getting a GRC solution “for free” without inspecting implementation and maintenance costs.
Getting a “free” GRC solution and not considering implementation time and overall costs is like getting a free, huge truck with two 48 ft. trailers and forgetting its outrageous fuel consumption and maintenance costs. It’s an expensive toy for handling regular tasks, and it could take a year and cost a fortune to even get it to your garage.
The solution: 
It needs to be mentioned that GRC project costs are comprised much more by implementation and maintenance costs than on the initial purchase. See for yourself by asking those that chose “free” GRC solutions what the total costs of their projects were. 
Ask Xpandion about cost effective GRC solutions. 
You will be surprised.
Mistake #5: 
The need for many, many SoD rules.
People think that because their company is large, its rule-set should include 1,000 or even 10,000 SoD rules. Not so. This creates the need for never-ending consulting and maintenance work and decreases the chance of finishing a successful SoD project on time.
The solution: 
Usually, only about 60 effective SoD rules are needed. 
If managed properly, the main business processes are not so different between large and small enterprises. So, if SoD rules are defined well, they shouldn’t grow even if the company does.
Get Xpandion’s software to control GRC. 
Click here for a demo

More Related Content

Recently uploaded

Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
daisycvs
 

Recently uploaded (20)

Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
 
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service AvailableBerhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
 
Puri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDING
Puri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDINGPuri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDING
Puri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDING
 
HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptx
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
 
Buy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail AccountsBuy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail Accounts
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
 
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur DubaiUAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
 
Getting Real with AI - Columbus DAW - May 2024 - Nick Woo from AlignAI
Getting Real with AI - Columbus DAW - May 2024 - Nick Woo from AlignAIGetting Real with AI - Columbus DAW - May 2024 - Nick Woo from AlignAI
Getting Real with AI - Columbus DAW - May 2024 - Nick Woo from AlignAI
 
WheelTug Short Pitch Deck 2024 | Byond Insights
WheelTug Short Pitch Deck 2024 | Byond InsightsWheelTug Short Pitch Deck 2024 | Byond Insights
WheelTug Short Pitch Deck 2024 | Byond Insights
 
Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...
Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...
Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...
 
KALYANI 💋 Call Girl 9827461493 Call Girls in Escort service book now
KALYANI 💋 Call Girl 9827461493 Call Girls in  Escort service book nowKALYANI 💋 Call Girl 9827461493 Call Girls in  Escort service book now
KALYANI 💋 Call Girl 9827461493 Call Girls in Escort service book now
 

Featured

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 

The 5 Most Astonishing Mistakes Made During GRC Projects in SAP Environments

  • 1. 5 Astonishing Mistakes Made During GRC Projects in SAP Environments Created by Xpandion SAP® is a registered trademark of SAP AG in Germany and in several other countries
  • 2. Moshe Panzer CEO, Xpandion Author
  • 3. Xpandion has software to quickly maintain GRC Prevent fraud, save costs, quickly ensure SoD/SOX compliance. •Automate in-house and outsourced auditing tasks. •Receive alerts about unusual activities. •Prevent security breaches, fraud and leakage of information. •Save an average of 30% on auditing costs. •Ensure a successful audit. Get a free demonstration of Xpandion’s ProfileTailor GRC software to see what makes Xpandion different.
  • 4. Mistake #1: The focus is on compensating controls, not on eliminating risk.
  • 5. People don’t want to solve SoD conflicts either because they fear upsetting the user, or because they don’t want to pay for external consultants. Focusing on compensating controls may be “more comfortable” but it doesn’t solve risk.
  • 6. The solution: Focus on solving the risks. Arm yourself with management support, GRC auditors and good consultants – but don’t be tempted to add compensating controls too quickly. Each control should be inspected first and then regularly inspected to ensure it’s still valid.
  • 7. Mistake #2: Only Risk Assessment Managers & Auditors care about eliminating GRC risks.
  • 8. GRC is a good thing. Its purpose is to decrease fraud and improve business processes. But, most people hate dealing with it. In the case of SOX compliance, many remove Power Users right before the audit and put them back right after. Anything to just get through. Shocking.
  • 9. The solution: Get organized and gain management support by working your way up the GRC project ladder. Step 1: SoD inspection Step 2: Narrow Power User authorizations Step 3: Track sensitive activities usage Step 4: Implement one- step emergency access process with auditing reports Step 5: Implement authorization-request process
  • 10. Mistake #3: After go-live, own developments are not treated properly.
  • 11. Most people set groups of activities in the initial GRC project implementation and do not maintain them regularly, typically because they’ve forgotten about them. This results in potential hidden violations to Segregation of Duties rules.
  • 12. The solution: Make it clear to management that the GRC project won’t be over at go-live as someone needs to keep an eye on the configuration, including enhancing the rule-sets according to new developments. It’s vital to add and update groups of activities over time. Use alerting software and get an alert when new objects appear in production. Then update the rule-set accordingly. Find out about Xpandion’s alerting software.
  • 13. Mistake #4: Getting a GRC solution “for free” without inspecting implementation and maintenance costs.
  • 14. Getting a “free” GRC solution and not considering implementation time and overall costs is like getting a free, huge truck with two 48 ft. trailers and forgetting its outrageous fuel consumption and maintenance costs. It’s an expensive toy for handling regular tasks, and it could take a year and cost a fortune to even get it to your garage.
  • 15. The solution: It needs to be mentioned that GRC project costs are comprised much more by implementation and maintenance costs than on the initial purchase. See for yourself by asking those that chose “free” GRC solutions what the total costs of their projects were. Ask Xpandion about cost effective GRC solutions. You will be surprised.
  • 16. Mistake #5: The need for many, many SoD rules.
  • 17. People think that because their company is large, its rule-set should include 1,000 or even 10,000 SoD rules. Not so. This creates the need for never-ending consulting and maintenance work and decreases the chance of finishing a successful SoD project on time.
  • 18. The solution: Usually, only about 60 effective SoD rules are needed. If managed properly, the main business processes are not so different between large and small enterprises. So, if SoD rules are defined well, they shouldn’t grow even if the company does.
  • 19. Get Xpandion’s software to control GRC. Click here for a demo